Spot a consent-phishing request — before you click Allow
Compose a fake "Microsoft Login" asking for everything, watch the risk banner explain why, then revoke it.
- 1
Load the "Phish" preset: an unverified client requesting files:write + mail:send + offline_access.
This is the shape of a real consent-phishing attempt — broad write/send access plus PERSISTENT offline_access, from a publisher nobody vouched for.
- 2
Run the assessment and read every fired signal, not just the risk banner.
Each signal names exactly why it fired — unverified_publisher_sensitive (the central red flag), over_broad, write_or_admin, persistent_access. Never a black box.
- 3
Grant it anyway, then open the connected-apps list below.
Consent is your call — transparency empowers the decision, it doesn't override it. But the risk you were shown is now a durable record you can review later.
- 4
Revoke the app you just granted.
Consent hygiene: reviewing and revoking apps you don't recognize (or no longer trust) is the other half of this defense, exactly like the real Connected-apps screen.
Learn the theory
🩻 X-ray — what actually happened
Your own insert-only audit trail — the real server events, sanitized (never a secret), each linked to the lesson that explains it.